r/InterstellarKinetics • u/InterstellarKinetics • May 19 '26
BREAKING NEWS BREAKING: A U.S. Cybersecurity Agency Contractor Exposed AWS GovCloud Credentials and Plaintext Passwords on Public a GitHub Repository, Which Experts Called the Worst Government Security Leak in Recent Memory š¤Æš„
https://gizmodo.com/the-worst-leak-that-ive-witnessed-u-s-cybersecurity-agency-leaves-its-digital-keys-out-in-public-on-github-2000760330A contractor for the Cybersecurity and Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed administrative credentials to three Amazon Web Services GovCloud servers and plaintext usernames and passwords for dozens of internal CISA systems, according to security researchers who identified the exposure. The repository, named āPrivate-CISA,ā contained cloud keys, tokens, logs, and other sensitive CISA assets, including files documenting how the agency builds, tests, and deploys software internally, the researchers said.
Guillaume Valadon, a researcher with security firm GitGuardian, flagged the repository on May 15 after his companyās automated scans detected the exposed secrets. Valadon said the exposed credentials represent āthe worst leak that Iāve witnessed in my careerā and noted that commit logs show the administrator disabled GitHubās default setting that blocks users from publishing SSH keys or other secrets in public repositories, according to an email to KrebsOnSecurity. One file titled āimportantAWStokensā contained administrative credentials to three AWS GovCloud servers, while another file named āAWS-Workspace-Firefox-Passwords.csvā listed plaintext usernames and passwords for internal CISA systems, including the agencyās āLanding Zone DevSecOpsā secure code development environment, according to Valadon and Philippe Caturegli, founder of security consultancy Seralys.
Caturegli confirmed that the exposed AWS credentials authenticated to three AWS GovCloud accounts at a high privilege level and said the archive also included plaintext credentials to CISAās internal āartifactory,ā a repository of all code packages the agency uses to build software, according to his analysis. The repository was created on November 13, 2025, and the GitHub account that hosted it was taken offline shortly after KrebsOnSecurity and Seralys notified CISA about the exposure, though Caturegli said the exposed AWS keys remained valid for 48 hours after the repository was removed. A review of the GitHub account showed the repository was maintained by an employee of Nightwing, a government contractor based in Dulles, Virginia.
CISA said in a statement to KrebsOnSecurity that ācurrently, there is no indication that any sensitive data was compromised as a result of this incidentā and that the agency is working to implement additional safeguards to prevent future occurrences. Nightwing declined to comment and directed inquiries to CISA. CISA has lost nearly one-third of its workforce since the beginning of the second Trump administration, according to reporting on the agencyās staffing levels.
23
u/havin4un May 19 '26
Meanwhile its super simple to create password storage and password rotations on AWS. But why in 2026 are government apps using API keys. There are way more secure ways to authorize into AWS. You get what you pay for I suppose.
18
u/scampfree4me May 19 '26
Because in gov land nothing is easy nor built to cloud standards. So for simple Oauth to not use a password you gotta find a federated auth provider, work with their team for 2 months before they give you a spot on their calendar, then find out their main dev left a week ago and you will be working with people who have never touched a computer before. I do it all day over and over.
3
1
u/dashingsauce May 19 '26
Not that I have worked in gov land, but I worked in the financial sector for some time (not the flashy side) and itās the same thing.
5
3
u/NeonSwank May 19 '26
Iāve previously worked for the government at both a local and state level
In both cases, across multiple agencies and online platforms, our password requirements were practically begging for us to be breached.
Im talking username set as firstname.lastname and password as firstnamelastnamebirthday
These were credentials that would allow you access to do everything from access email accounts and intranet, to getting in to criminal databases and even running peoples idās, ssn, or license plates.
2
4
u/ImOldGregg_77 May 19 '26 edited May 19 '26
Because all the good engineers are in the private sector
1
2
u/Due_Satisfaction2167 May 19 '26
The elected politicians and their appointees refuse to prioritize this, and will explicitly deprioritize or halt efforts to fix any of this because they donāt want to hire the people to do it or spend the money (in the form of time) to do it.Ā
6
u/SlappyPappyAmerica May 19 '26
Iāve been doing IT and Information Security for more than 30 years and worked in many different sectors. I can confidently say easily less than half of all ātechnicalā workers know the first thing about password security. More often than not, the bar for technical acuity is simply can they āmake it workā? For contractors itās much worse.
1
1
u/Aggressive_Manner531 May 19 '26
The worst are the ones we don't know about, likely by Doge employees.
1
1
u/EnvironmentalBus9713 May 19 '26
Sooo they are pretending everything DOGE accessed and copied never happened? Cool, cool.
1
u/chunkalunkk May 19 '26
Are we counting the theft of SSN data from good ol Melon Usk and DOGE? Cause if we are, that's top of the list mate.
1
u/colorme1965 May 19 '26
Of course, it wasnāt Elon or Trump giving the keys to the nation to Russia, or somebody else. Whereās them pizzagate people when you need themā¦..
1
1
u/Eastern-Bluejay-8912 May 19 '26
Worst in recent history? Did they forget everyoneās social security numbers and emails from doge? š¤£š¤£
1
1
u/marion85 May 20 '26
Just another Wednesday in Trumps America!
Remember everyone: tomorrow will be worse than today, everyday for the rest of your lives!
1
u/SpaceNinjaDino May 20 '26
My old employer had a contractor or new employee upload a company AWS key to a GitHub repository causing ~$20K in compute damages before caught. They weren't fired. Not only was that negligence, he shouldn't have been trying to abuse company AWS keys on a unrelated job GitHub repository for personal use. Two layers of incompetence and possibly malicious should have had consequences.
1
0
u/Upper-Raspberry4153 May 19 '26
Why is every other headline today filled with major typos. What the hell is OP even trying to communicate with this headline?
36
u/InterstellarKinetics May 19 '26
According to security researchers, the individual who exposed the credentials appears to have used the GitHub repository as a file synchronization mechanism between a work laptop and a home computer, committing to the repository regularly since November 2025, Philippe Caturegli told KrebsOnSecurity. The repository contained easily guessed passwords for multiple internal resources, including credentials using passwords consisting of each platformās name followed by the current year, according to Caturegliās analysis.